App. Ser.No.: 10/501,302 

Amendment in Response to Office Action dated October 30, 2006 



Amendments to the Claims 

The foliowing listing of the claims replaces all previous listings and versions of the claims 
in the application: 

5 Listing of the Claims 

1. (Currently Amended): A computer system for providing security awareness in 
an organization, comprising: 

a memory means, constituted by a hard disk or Random Access Memory device, 
1 0 a central processor unit connected to said memory means, 

an input device, constituted by a mouse or keyboard device, connected to said cen- 
tral processor unit, for the input of a piece of security infomiation into said computer sys- 
tem feF^teriH^^sai4iseewit^>4frfem 

15 an output device, constituted by a printer or display device, connected to said cen- 

tral processor unit for the output of security information, 

a policy module communicating with said input device and said memory means for 
the conversion of said piece of security information into an said information security ob- 
iec t. said information security object te-be stored in said memory means, and 

20 a survey module communicating with said memory means and said output means 

for generating from said information security object an element of a questionnary to be 
output by means of said output device. 

2. (Original): The computer system according to claim 1, fiirther comprising an 
25 educational module communicating with said memory means for receiving through said 

input device a set of answers to said questionnar}- and for comparing said set of answers of 
said questionary with said information security objects for determining the correct and the 
incorrect answers, and generating, based on said incorrect answers, an educational program 
to be output by m eans of said output device. 

30 

3. (Original): The computer system according to claim 2, said set of answers being 
stored in said memory means. 
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4. (Original): The computer system according to any of the claims 1-3, said mem- 
ory means being organized as a database. 

5. (Previously Presented): The computer system according to any of the claims 1- 
5 3, said computer system constituting a stand alone computer or alternatively a computer 

system including a network and a plurality of PC's each including an input device and an 
output device to be operated by a respective user. 

6. (Previously Presented): The computer system according to any of the claims 1- 
10 3, said centra! processor unit controls in said conversion of said piece of said security in- 
formation into said information security object, said policy module to check in said mem- 
ory means the possible presence of a corresponding security information object. 

7. (Currently Amended): A method of providing security awareness in an organiza- 

15 tion, comprising! the steps of 

providing receiving a piece of security' information, 

modularising said piece of security infonnation to create an information security 

object 

storing said piece of securit>^ information in a memor>' means as an information se- 
20 curity object in a memory means, said information security object being generated in a pol- 
icy module, 

generating in a survey module an element of a questionnary from said information 
security object^ and 

output outputting said questionnary including said element. 

25 

8. (Previously Presented): The method according to claim 7, further compris- 
ing of the computer system according to any of the claims 1-3. 

9. (New) A computer system for providing security awareness in an organiza- 
30 tion, comprising: 

a memory means coupled to a central processor unit; 

an input device coupled to said central processor unit for receiving security infor- 
mation into said computer system; 
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an output device coupled to said central processor unit for outputting security in- 
formation; and 

an information security object stored in said memory means, said information secu- 
rity object including modular content derived from said securit\ infomiation and having a 
5 unique identifier and security level value, said unique identifier used to link said informa- 
tion security object to an organization and said security level value used to create a security 
policy including the information security object which matches a default security level 
value of the organisation. 

10 10. (New) The computer system of Claim 9, further comprising a survey mod- 

ule communicating with said memory means and said output means for generating from 
said information security object an element of a questionnary to be output by means of said 
output device. 

15 11. (New) A method of providing security awareness in an organization, com- 

prising: 

receiving security information; 

modularising the security information to create an information security object; 
assigning a security level value to said information security object; and 
20 compiling said information security object into a security policy including other in- 

formation security objects having the same security level value. 
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